Cross-site scripting (XSS)
How injected scripts steal data and hijack sessions, and what stops them.
Open to opportunities
Ethical hacker and penetration tester
I test networks, applications and infrastructure for weaknesses, then write up how they break and how to close them. This site collects the articles, tutorials and reference sheets from that work.
Command line, services and everyday administration.
Protocols, scanning and how traffic actually moves.
Switching, routing and device configuration.
Methodology, recon and exploitation in authorised labs.
Using the framework, from first session to post-exploitation.
Injection, XSS and the other ways web applications fail.
Hardening, firewalls and keeping servers defensible.
How injected scripts steal data and hijack sessions, and what stops them.
Keep SSH closed until a sequence of connection attempts arrives in the right order.
Find open ports and running services, the starting point of most security audits.
My background is unikernel security research. I now build penetration-testing skills through hands-on labs and personal projects, and I like pulling systems apart to see exactly how they break.